PT-2013-1083 · Hewlett Packard+2 · Hplip+2

Published

2013-03-06

·

Updated

2024-06-15

·

CVE-2013-6427

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HPLIP versions 3.x through 3.13.11
Description The issue concerns multiple vulnerabilities in the HPLIP package of the Debian GNU/Linux operating system, which can be exploited by a local attacker to compromise the confidentiality, integrity, and availability of protected information. Specifically, the upgrade.py script in the hp-upgrade service launches a program from an http URL, allowing man-in-the-middle attackers to execute arbitrary code by gaining control over the client-server data stream.
Recommendations For HPLIP versions 3.x through 3.13.11, consider disabling the upgrade.py script in the hp-upgrade service until a patch is available to prevent man-in-the-middle attacks. Restrict access to the hp-upgrade service to minimize the risk of exploitation. Avoid using the http protocol for launching programs from URLs in the affected service until the issue is resolved.

Exploit

Fix

Link Following

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1475
BDU:2015-02622
CVE-2013-6427
DSA-2829-1
MGASA-2014-0033
OPENSUSE-SU-2024:10083-1

Affected Products

Alt Linux
Debian
Hplip